Privacy Policy
Esor finds job openings for you and, when you swipe right, completes and submits the application on your behalf. That means we handle your CV and the answers employers ask for. This policy explains exactly what we hold, why we are allowed to hold it, who else sees it, and how you get it back or get rid of it.
- Who we are
- Scope of this policy
- What we collect
- Why we use it, and our legal basis
- Sensitive information in your CV
- How AI is used
- Automated applications and profiling
- What employers receive
- Who else we share data with
- International transfers
- How long we keep data
- Your rights
- Deleting your account
- Security
- Our website, cookies and the waitlist
- Age limits
- Changes to this policy
- Contact and complaints
1. Who we are
The controller responsible for your personal data is the operator of Esor:
Esor
Email: privacy@esor.dev
Esor is a pre-launch product and the app is not yet available. Our operating entity is being established; its legal name, registered address and company registration number will be set out here, and this policy updated accordingly, before the app is released. Until then the only personal data we process is described in section 15.
Throughout this policy, "we", "us" and "Esor" mean that operator. "You" means the person using Esor.
We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR. Privacy questions go to the email address above and are handled by our management.
2. Scope of this policy
This policy covers the Esor mobile app, our website at esor.dev, and support correspondence with us. It does not cover what an employer, job board, or applicant tracking system does with an application after we have sent it on your behalf — once an application leaves Esor, the recipient becomes an independent controller of that data and its own privacy policy applies. See section 8.
3. What we collect
All of it comes either from you directly or is generated by your use of the app. We do not buy personal data, and we do not enrich your profile from external sources.
| Category | What it includes |
|---|---|
| Account | Email address, preferred name, and authentication metadata (sign-in timestamps, device type). Your password is stored only as a cryptographic hash by our authentication provider and is never visible to us. |
| Job preferences | Career stage, target roles and functions, industries, country and city, salary range, work mode, willingness to relocate. |
| Eligibility answers | Answers you explicitly give to questions employers commonly ask: work authorisation by country, whether you need visa sponsorship, notice period, salary expectations, and similar. |
| Your CV | The file you upload, and the information we read out of it — name, contact details, education, employment history, skills, and anything else you have chosen to put in it. |
| Applications | A record of every application we submit for you: the employer, the role, the date and time, the answers and documents sent, and the outcome if we learn of one. |
| Activity | Jobs shown to you, swiped, saved, or skipped; match scores; settings such as your daily application limit and any employers you have excluded. |
| Support | Messages you send us and our replies. |
| Technical | App version, operating system, crash diagnostics, and server log entries which include your IP address, needed to keep the service running and to prevent abuse. |
We do not collect location data, your contacts, your photo library, your microphone, your email mailbox, or advertising identifiers. Esor contains no advertising SDKs and no third-party analytics or tracking SDKs. We do not track you across other companies' apps or websites, and we do not sell or rent your personal data to anyone.
4. Why we use it, and our legal basis
Under the GDPR we need a lawful basis for every use of your data. Here is ours, purpose by purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account | Account | Contract — Art. 6(1)(b). We cannot provide Esor without it. |
| Finding, ranking and showing you job openings | Job preferences, CV, activity | Contract — Art. 6(1)(b). This is the service you signed up for. |
| Completing and submitting applications on your behalf | CV, eligibility answers, account, preferences | Contract — Art. 6(1)(b), performed on your instruction. See section 7. |
| Sensitive details contained in your CV | See section 5 | Your explicit consent — Art. 9(2)(a), given when you upload your CV. You may withdraw it at any time by deleting the CV. |
| Keeping a record of what was sent for you | Applications | Contract, and our legitimate interest — Art. 6(1)(f) — in being able to show you and ourselves what was submitted in your name. |
| Security, fraud prevention, abuse and rate-limit enforcement | Technical, activity | Legitimate interests — Art. 6(1)(f): protecting our users, employers, and our own service from misuse. |
| Fixing bugs and improving the app | Technical, aggregated activity | Legitimate interests — Art. 6(1)(f). We use aggregated or de-identified data for this wherever it is sufficient. |
| Answering your support requests | Support, account | Contract, and legitimate interests in responding to you. |
| Waitlist and launch announcement emails | Email address | Consent — Art. 6(1)(a). Withdraw any time via the unsubscribe link. |
| Meeting legal obligations and responding to lawful requests | As required | Legal obligation — Art. 6(1)(c). |
We do not use your personal data to train our own or anyone else's AI models. Where we rely on legitimate interests, you can object — see section 12 — and we will stop unless we have compelling grounds not to.
5. Sensitive information in your CV
Some information gets special protection under Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, plus genetic and biometric data.
Esor never asks you for any of it. But CVs often contain it anyway — a disability disclosure, a religious institution as an employer, a union role, a political internship, a photograph, or a date of birth. When you upload your CV, that content is stored and processed by us and passed to the employers you apply to.
Your explicit consent. By uploading a CV and enabling applications, you explicitly consent under Article 9(2)(a) GDPR to our processing any special category data your CV happens to contain, for the sole purpose of applying for jobs on your behalf. You can withdraw that consent at any time by deleting your CV or your account, which stops all further processing. Withdrawal does not affect applications already sent.
Our advice: keep it out. You do not need to include a photograph, date of birth, marital status, nationality, health information, religion, or political affiliation to apply for a job in the EU, and many employers prefer that you do not. Please do not put payment card numbers, bank details, national identity or social security numbers, or passport scans in your CV or in any answer — Esor has no use for them and no field asks for them.
Work authorisation and visa sponsorship answers are not, in themselves, special category data, but we treat them as sensitive because they can reveal a great deal about you. They are handled as described in the next section.
6. How AI is used
We use large language models to draft answers to open-ended application questions — the "tell us why you want this role" kind. To do that we send the model the minimum text needed: the question, the relevant parts of your CV and profile, and the job description.
- Eligibility questions are never sent to an AI model, and never inferred. Work authorisation, visa sponsorship, notice period, salary expectations, and similar questions are answered only from what you have explicitly told us. If you have not answered one, we leave it blank or skip the application. We never guess an answer that could misrepresent your right to work.
- No training on your data. Our model providers act as processors on our instructions under a data processing agreement, and are contractually prohibited from using your prompts or the generated output to train or improve their models.
- No decisions about you. The models draft text. They do not decide whether you are suitable for a role, and they do not score you as a person.
We are still finalising which model providers we use at launch. Rather than name a provider here and be wrong, we commit to this: we will publish and keep current the list of AI providers and other sub-processors that handle your data, and you can obtain it at any time by emailing privacy@esor.dev. We will not add a provider outside the EEA without a valid transfer mechanism in place as described in section 10.
7. Automated applications and profiling
This is the part of Esor you should understand best, so we are being blunt about it.
What happens when you swipe right
Swiping right is your instruction to us to apply for that job. We then complete the employer's application form and submit it without asking you to review it first. The application is sent in your name, as your statement, and reaches the employer as though you had filled the form in yourself. We do this because it is the service you asked for — but it means an application can be sent that you have not read word for word.
Profiling
We rank and filter job openings for you automatically, using your preferences, your CV, and how you have swiped before. That is profiling in the sense of Article 4(4) GDPR. Its only effect is which jobs appear in your feed and in what order. It does not restrict your ability to apply anywhere, and it produces no legal consequence for you.
Article 22 — automated decisions
Article 22 GDPR gives you protection against decisions about you, made solely by automated means, that have legal or similarly significant effects. Our automation does not make such a decision about you: it carries out a task you instructed us to perform, and it is our view that Article 22 is therefore not engaged by Esor's own processing. We are telling you about it anyway so you can make an informed choice.
What employers do is a different matter. Many employers and applicant tracking systems screen, score, or reject applications automatically. That processing is theirs, not ours, and we have no visibility of or control over it. Your Article 22 and information rights in relation to that screening are exercised against the employer.
The controls you have
- Review mode — you can require that every application is shown to you for approval before it is sent, instead of being submitted automatically.
- Pause and stop — you can pause all automated applications at any time, with immediate effect.
- Daily limit — a cap on how many applications may be sent for you in a day, which you set.
- Exclusions — you can block specific employers so we never apply to them.
- A full log — every application we send is recorded in the app, with the exact answers and documents that were submitted, so you can always see what was said in your name.
8. What employers receive
When we submit an application for you, the employer, job board, or applicant tracking system receives your name, your contact details, your CV, and your answers to that employer's questions. That is the point of the service, and it happens on your instruction.
This cannot be undone. Once an application has been sent, the recipient holds a copy of your data as an independent controller. We cannot retrieve it, edit it, or delete it, and deleting your Esor account does not delete it from the employer's systems. To have it erased you must contact the employer directly and exercise your rights against them. Please take this into account before enabling automated applications.
We do not share your data with employers in any other way. We do not operate a candidate database that employers can search, we do not offer your profile to recruiters, and we do not notify employers that you exist unless you have applied to them.
9. Who else we share data with
We use a small number of service providers, each acting as a processor under a written data processing agreement, permitted to use your data only on our instructions and only to provide their service to us.
| Provider | What it does | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage for the app | All app data, including your uploaded CV, which is held in a private storage bucket readable only by your own account |
| AI model providers | Drafting answers to open-ended application questions (section 6) | The question, relevant CV and profile extracts, and the job description. Never eligibility answers. |
| Vercel | Hosting our website, including this page | Server log data such as IP address, browser type, and pages requested |
| unpkg (Cloudflare) | Content delivery network serving JavaScript libraries used by our website | Your IP address and browser details, disclosed to the CDN when your browser requests those files. See section 15. |
| Brevo (Sendinblue SAS, France) | Storing waitlist sign-ups and sending account, transactional and launch emails | Email address and the message content. Brevo is established in the EU and stores this data within the EU. |
| Google Fonts | Serving the typeface used by our website | Your IP address and browser details, disclosed to Google when your browser requests the font files. See section 15. |
| Apple and Google | App distribution and crash reporting for the mobile app | Aggregate installation and crash data under their own privacy policies |
We will also disclose personal data where we are legally required to — a valid court order, or a binding request from a competent authority — and where necessary to establish, exercise, or defend legal claims. If we are ever involved in a merger or acquisition, your data may transfer to the acquirer, who will remain bound by this policy or give you notice of a replacement before any material change.
An up-to-date list of sub-processors is available on request from privacy@esor.dev.
10. International transfers
We aim to keep your data in the European Economic Area, and we host our database and file storage in an EEA region.
Some of our providers are established in the United States or may access data from outside the EEA to provide support. Where personal data is transferred outside the EEA, we rely on one of the following safeguards under Chapter V GDPR:
- the European Commission's Standard Contractual Clauses (Decision 2021/914), together with a transfer impact assessment and, where appropriate, supplementary technical measures such as encryption; or
- the provider's certification under the EU–US Data Privacy Framework, where it is certified for the relevant category of data; or
- an adequacy decision of the European Commission covering the destination country.
You can ask us which mechanism applies to a specific provider, and request a copy of the relevant safeguards, by emailing privacy@esor.dev.
11. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, preferences, eligibility answers | While your account is open. Deleted when you delete your account. |
| Uploaded CV | Until you replace it, delete it, or delete your account. |
| Application records | While your account is open, so you can see what was sent for you. Deleted when you delete your account. |
| Backups | Encrypted backups are retained on a rolling basis and fully overwritten within 30 days of deletion from our live systems. |
| Server and security logs | 12 months, then deleted. |
| Support correspondence | 24 months from the last message, then deleted. |
| Waitlist email address | Until we have sent the launch announcement, and in any event no longer than 12 months, or until you unsubscribe. |
| Records we must keep by law, or need to defend a legal claim | For the period required by the applicable law or limitation period, and no longer. |
Data already sent to an employer is outside this schedule and is retained according to that employer's own policy — see section 8.
12. Your rights
If you are in the EEA, the GDPR gives you the following rights. They are free to exercise, and we will respond within one month, as required by Article 12(3) — if a request is complex we may extend that by up to two further months and will tell you why.
- Access (Art. 15) — a copy of the personal data we hold about you, and confirmation of how we use it.
- Rectification (Art. 16) — correction of anything inaccurate or incomplete. Most of this you can do yourself in the app, and we encourage you to, because your profile is what gets sent to employers.
- Erasure (Art. 17) — deletion of your data. See section 13.
- Restriction (Art. 18) — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability (Art. 20) — receive the data you gave us in a structured, commonly used, machine-readable format, or have us send it to another provider where technically feasible.
- Objection (Art. 21) — object to processing based on our legitimate interests. You may object to direct marketing at any time and we will stop immediately, no questions asked.
- Withdraw consent (Art. 7(3)) — where we rely on consent, including the explicit consent covering sensitive CV content and marketing emails. Withdrawal is effective for the future and does not make earlier processing unlawful.
- Not to be subject to solely automated decisions with legal or similar effect (Art. 22) — see section 7 for how this applies.
- Complain (Art. 77) — to a data protection authority, as set out in section 18.
To exercise any of these, email privacy@esor.dev. We may need to verify your identity before acting, and we will only ask for what is necessary to do so.
13. Deleting your account
You can delete your account and its data at any time from inside the app: Profile → Delete account. No email, no form, no waiting for us.
Deletion removes your profile, preferences, eligibility answers, uploaded CV, application records, saved jobs, and login credentials from our live systems immediately, and it stops any automated applications at once. Encrypted backups are overwritten within 30 days as described in section 11. Deletion is permanent and we cannot restore an account afterwards.
Two things deletion does not do: it does not withdraw applications already submitted, and it does not delete your data from employers who have already received it. See section 8.
If you cannot reach the in-app option, email privacy@esor.dev and we will delete the account for you.
14. Security
We take the measures required by Article 32 GDPR, appropriate to the risk of handling CVs and application data:
- Data is encrypted in transit with TLS, and encrypted at rest by our hosting provider.
- Uploaded CVs are held in a private storage bucket. Access rules are enforced at the database level so that your rows and files are readable only by your own authenticated account.
- Passwords are never stored in readable form — only as salted hashes held by our authentication provider.
- Access to production systems is limited to those who need it, and protected by multi-factor authentication.
No service can promise perfect security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Article 33, and we will inform you directly without undue delay where Article 34 requires it.
15. Our website, cookies and the waitlist
Cookies. Our website sets no cookies and uses no analytics, advertising, pixels, session recording, or fingerprinting. Because we place nothing on your device that is not strictly necessary, there is no cookie banner to click through. If that ever changes, we will ask for your consent first, as Article 5(3) of the ePrivacy Directive requires.
Third-party files loaded by our website. To render the site, your browser currently requests two sets of files from third parties: JavaScript libraries from the public CDN unpkg.com, and the Inter typeface from Google Fonts. When your browser makes those requests, your IP address and browser details are necessarily disclosed to those providers, which may process them outside the EEA. Neither is used by us to track you, and we receive no data back from either. We rely on our legitimate interest in delivering a working website, and we are moving both onto our own domain so that no third-party request is made at all — after which this paragraph will be removed.
Server logs. Our host records standard request logs, including IP addresses, to serve the site and protect it from abuse. See section 11 for retention.
The waitlist. If you enter your email address to join the waitlist, it is stored by Brevo, an email platform operated by Sendinblue SAS in France, acting as our processor and holding the data in the EU. We use the address for one purpose only: to tell you when Esor launches. We will not send you unrelated marketing, and we will not pass it to anyone else. The legal basis is your consent, which you can withdraw at any time using the unsubscribe link in the email or by writing to us — and withdrawing it deletes you from the list.
16. Age limits
Esor is for adults. You must be at least 18 to create an account, because using Esor means authorising us to enter into correspondence and submit applications in your name, which requires the legal capacity to give that authority. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, email privacy@esor.dev and we will delete it and the associated data promptly.
17. Changes to this policy
If we change this policy we will update the version number and date at the top. Where a change is material — a new purpose, a new category of recipient, or a change in legal basis — we will notify you in the app or by email before it takes effect, and where the change requires your consent we will ask for it rather than assume it. Previous versions are available on request.
18. Contact and complaints
For anything in this policy, including exercising your rights: privacy@esor.dev. For general support: support@esor.dev. Postal address is in section 1.
Please give us the chance to put things right first. If you are not satisfied, you have the right under Article 77 GDPR to lodge a complaint with the data protection authority of the EU country where you live or work. A directory of all national authorities is published by the European Data Protection Board. You also have the right to an effective judicial remedy under Article 79.